Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:*:*:*", "matchCriteriaId": "A61CF72D-4323-4882-9B56-55692C54017D", "versionEndIncluding": "1.7.12", "versionStartIncluding": "1.7.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:*:*:*", "matchCriteriaId": "B835C5A9-9EC8-4C80-9192-6FD67C9527E9", "versionEndIncluding": "1.8.3", "versionStartExcluding": "1.8.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:electronjs:electron:2.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "88957B05-406B-4789-AD31-B9D82A1C56DD", "vulnerable": true}, {"criteria": "cpe:2.3:a:electronjs:electron:2.0.0:beta1:*:*:*:*:*:*", "matchCriteriaId": "88C71615-EFCF-41C6-AEEE-4D4C0AC8C8FB", "vulnerable": true}, {"criteria": "cpe:2.3:a:electronjs:electron:2.0.0:beta2:*:*:*:*:*:*", "matchCriteriaId": "EDDC6B3D-1ABD-4F15-BF25-C2C41507A1B1", "vulnerable": true}, {"criteria": "cpe:2.3:a:electronjs:electron:2.0.0:beta3:*:*:*:*:*:*", "matchCriteriaId": "D4E2CC9C-22C9-471E-986F-B4C325EF5017", "vulnerable": true}, {"criteria": "cpe:2.3:a:electronjs:electron:2.0.0:beta4:*:*:*:*:*:*", "matchCriteriaId": "3E1A9F01-84AC-45D8-AC93-03DB8EE27CE1", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have been fixed in 1.7.13, 1.8.4, 2.0.0-beta.4."}, {"lang": "es", "value": "Electron, en versiones desde la 1.7 hasta la 1.7.12, desde la 1.8 hasta la 1.8.3 y desde la 2.0.0 hasta la 2.0.0-beta.3, contiene una vulnerabilidad de gesti\u00f3n incorrecta de valores en Webviews que puede dar como resultado la ejecuci\u00f3n remota de c\u00f3digo. Parece que este ataque puede ser explotable mediante una app que permite la ejecuci\u00f3n de c\u00f3digo de terceros, no acepta la integraci\u00f3n de nodos y no especifica si la vista web est\u00e1 habilitada o deshabilitada. Esta vulnerabilidad parece haber sido solucionada en las versiones 1.7.13, 1.8.4, 2.0.0-beta.4."}], "id": "CVE-2018-1000136", "lastModified": "2024-11-21T03:39:45.697", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV30": [{"cvssData": {"attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.1, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0"}, "exploitabilityScore": 2.2, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2018-03-23T19:29:00.683", "references": [{"source": "cve@mitre.org", "tags": ["Mitigation", "Patch", "Vendor Advisory"], "url": "https://www.electronjs.org/blog/webview-fix"}, {"source": "cve@mitre.org", "tags": ["Exploit", "Third Party Advisory"], "url": "https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-1000136---Electron-nodeIntegration-Bypass/"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mitigation", "Patch", "Vendor Advisory"], "url": "https://www.electronjs.org/blog/webview-fix"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit", "Third Party Advisory"], "url": "https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-1000136---Electron-nodeIntegration-Bypass/"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-20"}], "source": "nvd@nist.gov", "type": "Primary"}]}